This trojan steals any information related to Brazilian Internet banking websites. The trojan uses a legitimate malware removal tool to maliciously remove some forms of security software that some Brazilian Internet banking websites require. The removal of the security software paves the way to allow the trojan to steal a user's credentials; the stolen credentials can then be forwarded to a remote server for further malicious use.
The trojan will also attempt to download and execute files from a remote server.
It then downloads and executes the legitimate removal tool, Avenger by Swandog. It also creates a number of files to facilitate the smooth execution of its activity. For example,
. The legitimate files that will be removed by Avenger are specified on the text file,
.
Of particular interest is GbPlugin, a program used by Brazilian banks to protect customers when they perform Internet banking transactions. Though normally difficult to remove, using the Avenger program allows the trojan to remove the GbPlugin at the next system startup or reboot.
• %systemdrive%\Arquivos de programas\GbPlugin\scpsssh2.dll
• %systemdrive%\Arquivos de programas\GbPlugin\gbiehuni.dll
• %systemdrive%\Arquivos de programas\GbPlugin\gbpdist.dll
• %systemdrive%\Arquivos de programas\GbPlugin\isg.gpc
• %systemdrive%\Arquivos de programas\GbPlugin\uni.gpc
• %systemdrive%\Arquivos de programas\GbPlugin\gbiehisg.dll
• %systemdrive%\Arquivos de programas\GbPlugin\GBIEHCEF.DLL
• %systemdrive%\Arquivos de programas\GbPlugin\scpVista.exe
• %systemdrive%\Arquivos de programas\GbPlugin\gbiehabn.dll
• %systemdrive%\Arquivos de programas\GbPlugin\GBIEHABN.DLL
• %systemdrive%\Arquivos de programas\GbPlugin\LOGOF.DLL
• %systemdrive%\Arquivos de programas\GbPlugin\abn.gpc
• %systemdrive%\Arquivos de programas\GbPlugin\AtmCap.ocx
• %systemdrive%\Arquivos de programas\GbPlugin\gbpsv.exe
• %systemdrive%\Arquivos de programas\GbPlugin\GbpSv.exe
• %systemdrive%\Arquivos de programas\GbPlugin\GbpSrv.exe
• %systemdrive%\Arquivos de programas\GbPlugin\gbpsrv.exe
• %systemdrive%\Arquivos de programas\GbPlugin\gbieh.dll
• %systemdrive%\Arquivos de programas\GbPlugin\gbieh.dll
• %systemdrive%\Arquivos de programas\GbPlugin\gbieh.gmd
• %systemdrive%\Arquivos de programas\GbPlugin\bb.gpc
• %systemdrive%\Arquivos de Programas\Scpad\scpMIB.dll
• %systemdrive%\program files\Scpad\scpsssh2.dll
• %systemdrive%\program files\Scpad\sshib.dll
• %systemdrive%\program files\Scpad\scpIBCfg.bin
• %systemdrive%\program files\Scpad\scpLIB.dll
• %systemdrive%\program files\scpsssh2.dll
• %systemdrive%\program files\gbiehuni.dll
• %systemdrive%\program files\gbpdist.dll
• %systemdrive%\program files\isg.gpc
• %systemdrive%\program files\uni.gpc
• %systemdrive%\program files\gbiehisg.dll
• %systemdrive%\program files\GBIEHCEF.DLL
• %systemdrive%\program files\gbiehabn.dll
• %systemdrive%\program files\GBIEHABN.DLL
• %systemdrive%\program files\LOGOF.DLL
• %systemdrive%\program files\abn.gpc
• %systemdrive%\program files\AtmCap.ocx
• %systemdrive%\program files\gbpsv.exe
• %systemdrive%\program files\GbpSv.exe
• %systemdrive%\program files\GbpSrv.exe
• %systemdrive%\program files\gbpsrv.exe
• %systemdrive%\program files\gbieh.dll
• %systemdrive%\program files\gbieh.gmd
• %systemdrive%\program files\bb.gpc
• %systemdrive%\program files\GbPlugin\Scpad\scpsssh2.dll
• %systemdrive%\program files\GbPlugin\Scpad\sshib.dll
• %systemdrive%\program files\GbPlugin\Scpad\scpIBCfg.bin
• %systemdrive%\program files\GbPlugin\Scpad\scpLIB.dll
• %systemdrive%\program files\GbPlugin\scpsssh2.dll
• %systemdrive%\program files\GbPlugin\gbiehuni.dll
• %systemdrive%\program files\GbPlugin\gbpdist.dll
• %systemdrive%\program files\GbPlugin\isg.gpc
• %systemdrive%\program files\GbPlugin\uni.gpc
• %systemdrive%\program files\GbPlugin\gbiehisg.dll
• %systemdrive%\program files\GbPlugin\GBIEHCEF.DLL
• %systemdrive%\program files\GbPlugin\gbiehabn.dll
• %systemdrive%\program files\GbPlugin\GBIEHABN.DLL
• %systemdrive%\program files\GbPlugin\LOGOF.DLL
• %systemdrive%\program files\GbPlugin\abn.gpc
• %systemdrive%\program files\GbPlugin\AtmCap.ocx
• %systemdrive%\program files\GbPlugin\gbpsv.exe
• %systemdrive%\program files\GbPlugin\GbpSv.exe
• %systemdrive%\program files\GbPlugin\GbpSrv.exe
• %systemdrive%\program files\GbPlugin\gbpsrv.exe
• %systemdrive%\program files\GbPlugin\gbieh.dll
• %systemdrive%\program files\GbPlugin\gbieh.gmd
• %systemdrive%\program files\GbPlugin\bb.gpc
• %windir%\scpVista.exe
• %windir%\gbpsv.exe
• %windir%\gbpsrv.exe
• %systemdrive%\Arquivos de programas\GbPlugin\GbpSrv.exe
• %systemdrive%\Arquivos de programas\GbPlugin\scpVista.exe
• %systemdrive%\avenger.txt
.
is created, containing the log of the removal process.
, will delete the backup files created by Avenger.
Once the security measures are removed, the trojan can proceed to its data stealing routine. When the user browses a targeted online banking website, the trojan is able to inject malicious HTML into the webpage. The injection allows the trojan to capture keystrokes the user enters into the log-in fields of the website, essentially stealing the user's credentials.
The stolen credentials are then sent to a number of e-mail addresses registered under VFEmail and Inbox.com: